[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Accepted mooix 0.4.1.12.1 (i386 source)



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Tue, 11 Jun 2002 11:45:03 -0400
Source: mooix
Binary: mooix
Architecture: source i386
Version: 0.4.1.12.1
Distribution: unstable
Urgency: low
Maintainer: Joey Hess <joeyh@debian.org>
Changed-By: Joey Hess <joeyh@debian.org>
Description: 
 mooix      - Unix is the moo.
Changes: 
 mooix (0.4.1.12.1) unstable; urgency=low
 .
   * Audited all stackless methods...
   * Reworked destroy again, closing additional holes that let a programmer
     call a guest's logout method successfully, and that let a programmer spoof
     the mooadmin's recycle_verb. The new destroy uses the objstack correctly
     and is safe from these types of spoofs.
   * Made thinglist->init not be raceable to set unprotected &etc fields.
   * Don't let just any programmer call ssh->setkey and pass it a key. Instead,
     introduce a sshkey field of avatars; setkey simply validates and copies
     that key into the ssh object. Changed setting of ssh keys to be done by
     saying: my sshkey is "blahblahblah". As a bonus, multiple keys can now be
     set, and keys can be unset, too.
   * safedeletefield calls _validate methods too, and its return value is now
     similar to safesetfield's.
   * ttysession page need not be stackless if the pagefile is created on init.
   * Make ttysession page and write (and log session write) read all parameters
     before locking anything, so an attacker cannot call them and block sending
     params to hang the session. Added a getallvals() to the C binding to
     facilitate this.
   * Made the single session prompt method not stackless, as there is no sane
     way to check its callers. Instead, make the parser know about single
     sessions, and abort after one line is read from them.
   * Fixed ttysession's write method's handling of very long unwrappable lines.
   * Fixed log session's handling of writes of more than one line at a time;
     prefix each line with its own timestamp.
   * Don't log self-emotes.
Files: 
 522dd481cd5b84dac42db7aae95bebf2 542 misc optional mooix_0.4.1.12.1.dsc
 d86215f430523a0e3f3a9c51e6079be2 333307 misc optional mooix_0.4.1.12.1.tar.gz
 d8d6768b6206c14a7255d44c2c082b4f 304026 misc optional mooix_0.4.1.12.1_i386.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)

iD8DBQE9Bpae2tp5zXiKP0wRAq9sAKC1BkepJQc+ZqfPckqMsvsJshaAIACgpWYo
DHskyrpde+Dpyp/ajtmh0V8=
=lBH0
-----END PGP SIGNATURE-----


Accepted:
mooix_0.4.1.12.1.dsc
  to pool/main/m/mooix/mooix_0.4.1.12.1.dsc
mooix_0.4.1.12.1.tar.gz
  to pool/main/m/mooix/mooix_0.4.1.12.1.tar.gz
mooix_0.4.1.12.1_i386.deb
  to pool/main/m/mooix/mooix_0.4.1.12.1_i386.deb


-- 
To UNSUBSCRIBE, email to debian-devel-changes-request@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org



Reply to: